Threat Brief: Information on Bad Rabbit Ransomware Attacks

This Unit 42 blog post provides an update on the threat situation surrounding the Bad Rabbit ransomware attacks.

 

Attack Overview

Bad Rabbit is a ransomware attack that, at the time of this writing, appears to primarily be affecting countries in Eastern Europe. While not spreading as widely as the Petya/NotPetya attacks, reports indicate that where Bad Rabbit has hit, it has caused severe disruption. The Ukrainian CERT has issued an alert on Bad Rabbit.

As detailed below, Bad Rabbit gains initial entry by posing as an Adobe Flash update. Once inside a network it spreads by harvesting credentials with the Mimikatz tool as well as using hard coded credentials.

Bad Rabbit is similar to Petya/NotPetya insofar as it encrypts the entire disk.

We are not aware of any reports of successful recovery after paying the ransom.

Because the initial attack vector is through bogus updates, Bad Rabbit attacks can be prevented by only getting Adobe Flash updates from the Adobe web site.

 

Reconnaissance

This attack does not appear to be targeted. Therefore, there appears to be little reconnaissance as part of this attack.

 

Delivery/Exploitation

According to ESET, the initial infection vector for Bad Rabbit is through a fake Adobe Flash update that is offered up from compromised websites. Proofpoint researcher Darien Huss‏ has reported this fake update was hosted at 1dnscontrol[.]com. Reports differ on whether this is delivered through social engineering that convinces the user to install the fake update or if it is delivered silently through unpatched vulnerabilities (i.e. “drive-by” installs).

 

Lateral Movement

Once inside a network, Bad Rabbit propagates itself to other systems. Reports indicate that it harvests credentials using Mimikatz and Maarten van Dantzig reports it also uses common hardcoded credentials to spread.

 

Command and Control (C2)

At this time, we have no information on command and control for Bad Rabbit.

 

Conclusion

Bad Rabbit is not as widespread of an attack as Petya/NotPetya but is causing severe disruptions where it is occurring. It is similar to Petya/NotPetya in terms of the impact of a successful attack. However, it is a different attack with different malware.

We will update this blog with new information as it becomes available.

For information on how Palo Alto Networks products prevent Bad Rabbit, please see our Palo Alto Networks Protections Against Bad Rabbit Ransomware Attacks blog post.

As always if you have any questions, please come to the Threat & Vulnerability Discussions on our Live Community.

 

Version Summary

October 24, 2017 2:30 p.m. PT

  • Initial Publication

[Palo Alto Networks Research Center]

Threat Brief: Drive-by Mining – Adapting an Old Attack to Mine Cryptocurrencies

On January 2, 2017, one Bitcoin was worth US $985.56.

By October 16, 2017, that same Bitcoin was worth US $ 5,707.40: a 579% increase in value in ten and a half months.

By comparison, Ethereum has gone from US $8.15 per ether on January 2, 2017 to US $342.83 per ether on October 16, 2017: a jump of 4,206%.

Cryptocurrencies are big money these days and seemingly getting bigger by the day.

And if we’ve learned one thing about cybercriminals, they follow the money.

So, it’s not surprising to see that cybercrime is turning its attention to cryptocurrencies.

In our latest research, “Unauthorized Coin Mining in the Browser”, Unit 42 researchers show how cybercriminals have taken an old tactic, hijacking web browsers without the users consent or knowledge (commonly called a “drive -by attack”), and adapted it to make money in the increasingly lucrative cryptocurrencies markets.

Before, drive-by attacks focused on abusing a browser’s legitimate download capabilities to download malware onto the victim’s system without their consent or knowledge. These new drive-by attacks focus on hijacking the computational resources of the victim’s computer to “mine” cryptocurrency on behalf of the attackers.

The focus of these attacks is to use the victim’s web browser to access the computational resources of their system. The attackers accomplish this through abuse of a legitimate tool by placing it on malicious or compromised websites and running it in the victim’s browser without his or her consent or knowledge when they visit the site. The tool is designed to “mine” cryptocurrencies, that is it earns credit in the cryptocurrency in exchange for computing power that is used to power the cryptocurrencies’ digital infrastructure. This tool has a legitimate use: sites can and do notify users that they’re using the site visitors’ resources in this way to support the site, typically as a substitute for ads on the site. But in this case, the attacker actually gets the credit that the victim’s computational resources earns without the visitors’ consent or knowledge making it a malicious attack.

Put simply, the net result is that the victim’s computer slows down (sometimes significantly) while on the malicious or compromised website. And while the computer is impacted like this, the attacker is earning money. The attacker steals the victims computing resources and translates it into a cryptocurrency like Bitcoin.

This new kind of attack tells us that at least some cybercriminals are starting to view theft of victim’s computing power to translate into cryptocurrencies as a better business proposition than the traditional practice of loading malware on the victim’s system through drive-by downloads.

And our research shows that this isn’t an isolated event. Our researchers analyzed over 1,000 of sites and what they found was very telling.

  1. According to Alexa, 5 of these sites ranked in the top 2K of sites, 29 sites in top 10K and 155 sites in top 1 million.
  2. While many of these sites can be dated back to 2013, we saw steady level to the number of sites until October 2017:  then we saw 502 (63%) of these domains spring up suddenly.
  3. We found these malicious and compromised sites resolved to 47 different counties with the majority being in the United States.
  4. The greatest number of victims we could identify come from the Eastern United States with the Western United States in second. Europe and Asia Pacific came in third and fourth respectively.
  5. In terms of the domains where we found these malicious and compromised sites, .download and .bid domains accounted for the majority, comprising more than 35% of these sites. .com and .review tied for 3rd with 13% of the sites each.

The good news is that these attacks are more like denial of service attacks: they don’t do lasting harm to your system and they end when you leave the site.

The bad news is that these are harder to defend against than typical drive-by download attacks. Where drive-by download attacks usually exploit unpatched vulnerabilities, the root of these attacks is that they abuse otherwise legitimate functionality: you can’t prevent them by being fully patched.

Security products that take a comprehensive, layered approach can help prevent these attacks. And if you think your system is being affected by one of these attacks, you can, in most cases, end the attack by either leaving the site or closing the browser.

Most of all, this latest development shows how a changing economic landscape in turn changes the cybercrime landscape. Loading malware through drive-by downloads is so 2012: in 2017 it’s about drive-by mining attacks to earn cryptocurrencies.

[Palo Alto Networks Research Center]

Welcoming the APAC WildFire Cloud

In service of delivering superior security outcomes, we must aggregate massive quantities of unknown threat data from a global community of users. Once this data is brought together, it should be rapidly processed, correlated and acted upon as new prevention controls. In order to support thousands of customers and petabytes of data in one central location, this type of capability is ideally suited to a cloud-delivered security model, ensuring customers don’t need to build or operationalize infrastructure required to run the system, as well as enabling seamless sharing and correlation of data.

However, inherent in delivering this type of capability through the cloud is ensuring that customers everywhere can consume it, regardless of their local data privacy or sovereignty requirements. In support of our customer’s local needs, we are proud to announce the APAC WildFire cloud, located in Singapore, which further extends our regional cloud approach to now cover Asia-Pacific (APAC), the European Union (EU), Japan and North America.

Customers can now choose to execute unknown samples using:

  • Any one of our regional clouds (US, APAC, EU and Japan)
  • Private cloud with an on-premise WildFire appliance
  • Hybrid mode, combining the regional cloud with on-premise WildFire appliances

When choosing a regional cloud, customers will maintain their data locally, while still sharing protections automatically with more than 19,000 other WildFire customers. This approach capitalizes on WildFire’s unique cloud-delivered security services model, allowing us to develop and deploy innovative technology without putting a heavy burden on customers to make changes to their local infrastructure, regardless of their location in the world.

Uniquely, WildFire turns the entire Palo Alto Networks Next-Generation Security Platform into a massively distributed set of sensors across the network, endpoint and cloud, ensuring complete visibility and ability to enforce protections wherever the customer’s users and data reside. As part of the platform and the community-driven approach WildFire has always employed, all of the globally correlated intelligence is available within our AutoFocus contextual threat intelligence service, providing the ability to quickly hunt across collected data to speed security workflows.

The addition of the APAC WildFire cloud ensures organizations who are based, or have a presence in, Asia-Pacific can benefit from WildFire and AutoFocus, while supporting local data privacy or sovereignty requirements. We encourage existing customers in the region to begin submitting samples to the APAC cloud now, by simply changing the URL for the WildFire public cloud to https://sg.wildfire.paloaltonetworks.com/ within the WildFire settings on your next-generation firewalls.

[Palo Alto Networks Research Center]

Palo Alto Networks Day Japan 2017: Evolving Cybersecurity Efforts to Increase Trust in the Digital Age and Prevent Cyberattacks

Palo Alto Networks Day 2017, our third annual global cybersecurity conference in Japan, was a great success, attracting over 2,600 registrations. The number of attendees has more than doubled each year of the conference; and the spike in attendance reflects growing interest in cybersecurity updates on next-generation technology, the current cyberthreat landscape, Japan’s cybersecurity policy, cloud and IoT security, and the protection of critical infrastructure. Keynote speakers repeatedly referred to the importance of agility, automation, and cyberthreat intelligence sharing.

Mark McLaughlin, chief executive officer and chairman of Palo Alto Networks, emphasized in his keynote that we live in the digital age, meaning our businesses rely on digital technologies to increase our productivity on a global basis. Adversaries are taking advantage of the declining costs of launching automated cyberattacks and are doing so at high speeds, whereas defenders are suffering from the growing complexity of cyberthreats and depend on manual responses. This can lead to eroding trust and decreasing productivity. That is why there has been an increased focus on cybersecurity platforms over the last ten years to pursue automation, innovation, orchestration, and cyberthreat intelligence sharing to prevent successful cyberattacks.

No single company can address all of the complexities of cybersecurity and be responsible for all the innovations needed to secure the digital age. The market finds it challenging to access and absorb the latest solutions. Mark shared an example of the disruptive evolution of cybersecurity solutions to address these issues: Palo Alto Networks Application Framework. This offering was launched four months ago to allow any vendor to develop applications for the framework and access a massive amount of data. Users do not need to deploy anything to their environment. All they have to do is turn on the application they want to use. As of today, more than 30 vendors contribute to the Application Framework, and we expect this community of developers to grow.

We also heard from an end-user company, Recruit Technologies Co. Ltd., who shared their IT and cybersecurity journey from the last few years. They consolidated their data centers, increased automation, and shifted from private to public cloud for agility and flexibility. Mr. Hiroshi Hoshina, IT Solutions Control division from Recruit Technologies, explained how his company uses access control, segmentation, and Palo Alto Networks products to enhance their cybersecurity. While network infrastructure used to only focus on its functions and operational stability, consumers now demand more agility after the invention of virtual technologies, and software-defined agility is more appreciated.

We also had two researchers from Unit 42, our threat intelligence team, speak about the current cyberthreat landscape. Brad Duncan shared his observations of the wide-scale distribution of information-stealing malware and ransomware, and encouraged the audience to apply such best practices as patching, regular backup, and browsing restrictions.

Kaoru Hayashi acknowledged the steady growth of cyberthreats, tactics, and tools, and culprits have been able to create an underground ecosystem to divide their work roles and take advantage of online anonymity, and automated and cheap technologies, to launch various attacks. He emphasized that cyberattackers have to be successful all the way through their attack lifecycle to achieve their malicious goal, and defenders need to utilize cyberthreat intelligence to cripple their malicious intent and moves at any of the attack lifecycle stage before they succeed. Without cyberthreat intelligence, leadership can neither elucidate what risks their organization currently faces nor decide on what needs to be done. Organizations need technologies, automation to share cyberthreat intelligence effectively, and people who understand the importance of such intelligence to bridge the gap between engineers and leadership.

Palo Alto Networks would like to thank all of the attendees, speakers, and our sponsors for your contributions to increasing cybersecurity awareness, and for making this a successful event. We look forward to welcoming you all back to Palo Alto Networks Day 2018 in Tokyo next year!

[Palo Alto Networks Research Center]

Threat Brief: Patch Today and Don’t Get Burned by an Android Toast Overlay

Today, Palo Alto Networks Unit 42 researchers are announcing details on a new high- severity vulnerability affecting the Google Android platform. Patches for this vulnerability are available as part of the September 2017 Android Security Bulletin. This new vulnerability does NOT affect Android 8.0 Oreo, the latest version; but it does affect all prior versions of Android. There is some malware that exploits some vectors outlined in this article, but Palo Alto Networks Unit 42 is not aware of any active attacks against this particular vulnerability at this time. Since Android 8.0 is a relatively recent release, this means that nearly all Android users should take action today and apply updates that are available to address this vulnerability.

What our researchers have found is a vulnerability that can be used to more easily enable an “overlay attack,” a type of attack that is already known on the Android platform. This type of attack is most likely to be used to get malicious software on the user’s Android device. This type of attack can also be used to give malicious software total control over the device. In a worst-case attack scenario, this vulnerability could be used to render the phone unusable (i.e., a “brick”) or to install any kind of malware including (but not limited to) ransomware or information stealers. In simplest terms, this vulnerability could be used to take control of devices, lock devices and steal information after it is attacked.

An “overlay attack” is an attack where an attacker’s app draws a window over (or “overlays”) other windows and apps running on the device. When done successfully, this can enable an attacker to convince the user he or she is clicking one window when, in fact, he or she is actually clicking another window. In Figure 1, you can see an example where an attacker is making it appear that the user is clicking to install a patch when in fact the user is clicking to grant the Porn Droid malware full administrator permissions on the device.

Figure 1: Bogus patch installer overlying malware requesting administrative permissions

You can see how this attack can be used convince users to unwittingly install malware on the device. This can also be used to grant the malware full administrative privileges on the device.

An overlay attack can also be used to create a denial-of-service condition on the device by raising windows on the device that don’t go away. This is precisely the type of approach attackers use with ransomware attacks on mobile devices.

Of course, an overlay attack can be used to accomplish all three of these in a single attack:

  1. Trick a user into installing malware on their device.
  2. Trick a user into giving the malware full administrative privileges on the device
  3. Use the overlay attack to lock up the device and hold it hostage for ransom

Overlay attacks aren’t new; they’ve been discussed before. But until now, based on the latest research in the IEEE Security & Privacy paper, everyone has believed that malicious apps attempting to carry out overlay attacks must overcome two significant hurdles to be successful:

  1. They must explicitly request the “draw on top” permission from the user when installed.
  2. They must be installed from Google Play.

These are significant mitigating factors and so overlay attacks haven’t been reckoned a serious threat.

However, our new Unit 42 research shows that there is a way to carry out overlay attacks where these mitigating factors don’t apply. If a malicious app were to utilize this new vulnerability, our researchers have found it could carry out an overlay attack simply by being installed on the device. In particular, this means that malicious apps from websites and app stores other than Google Play can carry out overlay attacks. It’s important to note that apps from websites and app stores other than Google Play form a significant source of Android malware worldwide.

The particular vulnerability in question affects an Android feature known as “Toast.” “Toast” is a type of notification window that “pops” (like toast) on the screen. “Toast” is typically used to display messages and notifications over other apps.

Unlike other window types in Android, Toast doesn’t require the same permissions, and so the mitigating factors that applied to previous overlay attacks don’t apply here. Additionally, our researchers have outlined how it’s possible to create a Toast window that overlays the entire screen, so it’s possible to use Toast to create the functional equivalent of regular app windows.

In light of this latest research, the risk of overlay attacks takes on a greater significance. Fortunately, the latest version of Android is immune from these attacks “out of the box.” However, most people who run Android run versions that are vulnerable. This means that it’s critical for all Android users on versions before 8.0 to get updates for their devices. You can get information on patch and update availability from your mobile carrier or handset maker.

Of course, one of the best protections against malicious apps is to get your Android apps only from Google Play, as the Android Security Team aggressively screens against malicious apps and keeps them out of the store in the first place.

[Palo Alto Networks Research Center]

English
Exit mobile version